Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Another FTP DMZ question

Status
Not open for further replies.

wilson2468

Technical User
Jun 2, 2006
84
US
I cannot find the problem.

I am trying to create a DMZ on a PIX 515E 7.1.

The Interface is up, but no hosts in the DMZ, I am just trying to ping the Interface from an Inside network at the moment.

Debugs show the ICMP packets getting to the interface, but they do not return to the machine in the Inside network they are originating from.

I am not sure of the exact logic, but believe:


To let traffic flow from a high security level to a lower level, use the nat and global commands, here is what I have
(Inside Interface is actually 10.10.154.0, on a Cisco 4503, but packet will originate from a 10.10.151.0 network)


nat (DMZ_1) 1 172.30.100.0 255.255.255.0
global (DMZ_1) 1 172.30.100.100-172.30.100.254 netmask 255.255.255.0


For the opposite direction, from lower to higher, use the static and access-list commands,


static (inside,DMZ_1) 10.10.151.0 10.10.151.0 netmask 255.255.255.0
access-group DMZ_1_access_in in interface DMZ_1
 
Take a look at this chapter in the "Cisco PIX Firewall Configuration Guide, Version 6.0":
I know it is the wrong software version, but I was not able to find the document for version 7.1 I still don't have mine configured completely, but I found this really helpful.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top